>To the GFW, these 8 ApplicationData records could look like 4 pairs of HTTP requests and responses in a keep-alive connection. However as research has shown [5] [6], side-channel leaks in TLS can be exploited, for example by looking at packet sizes. Doing so, we can see that they indeed match the expected sizes of the messages exchanged during a CONNECT request and a TLS handshake:
As someone who crack (or at least block) VPN protocols for a living, I can indeed confirm this is 1 of the tricks used by all deep-inspection firewalls to detect VPNs.
In fact, a very popular VPN software for Chinese citizens uses TLS-within-TLS (sometimes fake TLS) to hide its data. From the author's description, the traffics are similar enough IMO for the GFW to detects.
(No, I don't work on GFW, but we block similar software. Sometimes we do comparison between various products to see how others block them.)